Executive brief
A vulnerability has been identified in QNAP operating systems used to manage Network Attached Storage (NAS) devices. A remote attacker could exploit this flaw to cause the system to crash or become unresponsive, leading to a denial-of-service. This impact prevents legitimate users from accessing stored data or using network services until the system is recovered.
Technical details
A NULL pointer dereference (CWE-476) exists in several QNAP operating system versions, including QTS and QuTS hero. The vulnerability can be triggered by a remote attacker over the network without requiring authentication or user interaction. Successful exploitation leads to a denial-of-service (DoS) by causing the affected system component to crash. QNAP has released security updates for QTS 5.2.9, QuTS hero h5.2.9, h5.3.4, and h6.0.0 to address this issue.
Affected products
- QNAP Systems, Inc. QTS 5.2.x versions prior to 5.2.9.3410 build 20260214
- QNAP Systems, Inc. QuTS hero h5.2.x prior to h5.2.9.3410 build 20260214; h5.3.x prior to h5.3.4.3500 build 20260520; h6.0.x prior to h6.0.0.3397 build 20260206
Timeline
- 2026-06-10: disclosed
- 2026-06-10: advisory